首页> 外国专利> System for determining the rights of object access for a server process by combining them with the rights of the client process

System for determining the rights of object access for a server process by combining them with the rights of the client process

机译:通过将服务器进程与客户端进程的权限相结合来确定对象访问权限的系统

摘要

In a multitasking, multiuser computer system, a server process temporarily impersonates the characteristics of a client process when the client process preforms a remote procedure call on the server process. Each process has an identifier list with a plurality of identifiers that characterize the process. The server process generates a new identifier list which is either the same as the client process's list, or is the union of the server's and the client's lists. Each object in the system can have an access control list which defines the identifiers that a process must have in order to access the object. The operation system has access checking software for enabling a selected process access to a specified object when the identifiers for the process match the list of identifiers in the access control list of the specified object. The server can therefore access all objects accessible to the client while the server is working for the client. The server can restore its original identifier list after completing the services that it performs for the client.
机译:在多任务,多用户计算机系统中,当客户端进程在服务器进程上执行远程过程调用时,服务器进程会临时模拟客户端进程的特性。每个进程都有一个标识符列表,其中包含多个表征该进程的标识符。服务器进程生成一个新的标识符列表,该标识符列表与客户端进程的列表相同,或者是服务器列表和客户端列表的并集。系统中的每个对象都可以具有一个访问控制列表,该列表定义了进程访问该对象必须具有的标识符。操作系统具有访问检查软件,用于在进程的标识符与指定对象的访问控制列表中的标识符列表匹配时,使选定的进程能够访问指定对象。因此,在服务器为客户端工作时,服务器可以访问客户端可访问的所有对象。服务器完成为客户端执行的服务后,可以恢复其原始标识符列表。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号